Also known as: Jripbot, Morpho, Butterfly, Sphinx Moth
**Toolset/Malware:** Jiripbot, Hesperbot
Sphinx Moth
Executive Summary
Wild Neutron, an APT group linked to nation-state activities, primarily focuses on espionage through the use of malware such as Jiripbot and Hesperbot. This actor exhibits a high level of technical proficiency, targeting critical sectors in select countries with sophisticated attack vectors. Their operations are characterized by long-term campaigns aimed at data exfiltration and intelligence gathering.
Goals & Targeting
Wild Neutron’s primary motivation appears to be espionage, with a focus on gathering sensitive information from targeted industries. The group selects victims based on their ability to provide valuable intelligence to the nation-state sponsor. Their targeting strategy likely aligns with national security priorities, focusing on sectors such as government, defense, and critical infrastructure.
Enhanced Description
Wild Neutron is a persistent threat group known for its nation-state affiliations and focus on espionage activities. The group operates with a high degree of technical sophistication, employing custom malware like Jiripbot and Hesperbot to compromise targets. These tools are typically used in targeted attacks against government entities, defense organizations, and critical infrastructure sectors. Wild Neutron’s campaigns are characterized by their patient persistence and use of advanced tactics to maintain access and avoid detection. The group's activities suggest a strategic approach to targeting specific sectors and countries, likely aligned with geopolitical interests.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Wild Neutron is known for its long-term operational persistence, often maintaining access to compromised networks for extended periods. The group's campaigns are likely tied to specific geopolitical events or intelligence-gathering objectives. Notable past operations include targeted attacks against government and defense sector entities, with a focus on data collection and exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Low confidence in the exact nature of Wild Neutron's operations due to limited公开 reporting. While the group's toolset and aliases suggest a high level of sophistication, further details on their specific TTPs are unclear. Additional data on campaign patterns and specific victims would improve understanding.
No techniques linked yet.
Sphinx Moth
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
2
Tools
1
Campaigns
0
IOCs
0
Observed Data
0
Tactics